Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-73Definition on MITRE ↗Clear

5 results

CVE-2025-33053
2025-06-10
Microsoft Windows External Control of File Name or Path Vulnerability
Microsoft

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.

CWE-73
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-07-01
CVE-2025-24054
2025-04-17
Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
Microsoft

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.

CWE-73
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-05-08
CVE-2025-0111
2025-02-20
Palo Alto Networks PAN-OS File Read Vulnerability
Palo Alto Networks

Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.

CWE-73
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2025-03-13
CVE-2024-43451
2024-11-12
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
Microsoft

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

CWE-73
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-12-03
CVE-2020-1631
2022-03-25
Juniper Junos OS Path Traversal Vulnerability
Juniper

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

CWE-22 · Path traversalCWE-73
Refsnvd.nist.gov
Federal remediation due 2022-04-15